Back to Catalog
151 of 226
PS 26151SOFTWAREBlockchain & CybersecurityFast Prototype (36h)

Dark web threat actor de-anonymization

National Technical Research Organisation (NTRO)National Technical Research Organisation (NTRO)
Google Search
30-Second Plain English Summary

Hostile threat actors, ransomware cartels, and cyber espionage groups operate behind Tor onion routing, PGP encryption, and cryptocurrency mixers on the dark web, leaving intelligence analysts with fragmented alias trails. Build a Dark Web Threat Actor De-Anonymization and Intelligence Correlation Platform for NTRO that crawls hidden onion services, analyzes PGP key cross-references, extracts digital styling fingerprints (stylometry), and maps cryptocurrency transactions to de-mask adversary identities across surface and dark web platforms.

5-Dimension Strategic ScorecardOverall Score: 4 / 5.0
Innovation
4.1 / 5
36h Feasibility
4.5 / 5
Uniqueness
3.9 / 5
Jury Appeal
3.8 / 5
Tech Depth
3.6 / 5
Recommended System Architecture Pipeline
Tor Network Crawlers -> Raw Dark Web Data Lake (Elasticsearch) -> PGP / Crypto / Metadata Extractor -> Stylometry AI & Neo4j Entity Graph -> NTRO Threat Actor Console
Recommended Tech StackClick to search similar
Official Government Problem Description
• Background The dark web has become a preferred operating space for threat actors in the modern age, mainly because it lets them hide their identity behind Tor hidden services, which makes attribution of threat actors operating on darkweb the main challenge for any investigation. Such threat actors carry out a wide range of unlawful activities such as drugs and arms sale, stolen data and hacking services, money laundering, terror financing, etc. The objective of this problem statement is to build a system for the deanonymization of dark web threat actors and link them to suspect real-world entities. • Description The system shall deanonymize dark web threat actors by continuously gathering their footprints from a range of sources (marketplaces, forums, deep web etc.) and linking them to the identifying information available on those sources. The system envisages three core capabilities. First, finding misconfigurations in Tor hidden services"”such as exposed server-status pages, SSL certificates tied to clearnet domains, default service banners, descriptor inconsistencies, etc and matching them with clearnet infrastructure to point to the likely origin servers. Second, mapping threat actors across multiple marketplaces into a single relationship graph of handles, PGP keys, wallets and trust links. Third, using AI-based analysis, including stylometric persona identification and behavioural profiling, to link rebranded or migrated personas to known threat actors. The system shall provide an analytical front end to query the database across a chosen timeline and shall work in an autonomous mode, drawing on available sources of good quality and reliability. • Expected Solution An end-to-end system shall be developed for the collection, storage, contextualization and querying (through GUI/dashboards) of dark web threat actor intelligence"”covering actor profiles, identifiers (handles, PGP keys, wallets etc.), hidden service infrastructure indicators, persona linkages, attribution confidence, category, last scan date and source. The system shall also provide the facility to export the result set in CSV, JSON and report formats.
AI & PPT Citation Format

Smart India Hackathon 2026 Problem Statement PS-26151: "Dark web threat actor de-anonymization", Ministry: National Technical Research Organisation (NTRO). Strategy & Architecture via SIH ONE (https://sihone.pages.dev/ps/26151)

Related Problem Statements in Blockchain & Cybersecurity